Failed Login Firewall reporting

Plugin Banner

Failed Login Firewall reporting

by Anton Aleksandrov

Download
Description

Idea of this plugin is simple. On failed login attempt – report IP of visitor to centralized database.
If same IP fails a lot (no matter on which site) – it will be listed on blocklist.

CSF (Config Server Firewall) allows you to put URL which contains list of IPs, that should be blocked.
Set it to our address and your server will be protected from those, who abuse WordPress sites login forms.

Plugin is simple and I believe it can become an effecient tool fighting against hackers, as it would
stop bad guys at firewall level, not letting them do any harm.

  1. Upload the plugin files to the /wp-content/plugins/plugin-name directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress
What will be reported

Failed login and IP address of visitor.

How can I use your list on my firewall

Set firewall script, e.g. CSF to fetch list of abuser IPs from here http://wp-firewall.hosting.guru/deny.txt

What is deny policy

IP will be listed in deny list if it matches any of the following
* more than 20 failed login attempts since yesterday 00:00
* more than 100 failed login attempts within last 10 days
* more than 500 failed login attempts within last 30 days

Basically if some IP failed 500 times or more – it will be blocked for at least 30 days.

Veldig smart brannmur

By Zondo Norge AS (Zondo.no) on September 3, 2016

Blir smartere desto flere som har den 🙂

Alle bør ha denne installert!

By Gudjon Gudjonsson (gudjon) on September 3, 2016

Jo flere wordpress som har denne installert, jo bedre! Blir en wordpress angrepet og hacker blokkert - så blir den jo blokkert for alle andre som bruker denne plugin! Fantastisk!

0.32

  • Minor syntax fix

0.3

  • Compatability update

0.2

  • Ready to publish on wordpress.com

0.1

  • First version for testing on private sites.
Back to top